Disabling SMS as a second factor for 2FA

Updated 2 days ago by admin

SMS will be deprecated in the Cloud MFA product by the end of August 2025

While SMS-based two-factor authentication (2FA) was once a major step forward for account security, it's now widely recognised as an insecure and outdated method for protecting sensitive accounts. Many high-profile breaches have exploited the vulnerabilities of SMS, and cybersecurity experts and government agencies now strongly advise against relying on it for authentication.

SMS is vulnerable to attacks such as SIM swapping or cloning, SMS interception and man-in-the-middle attacks, with several high profile organisations falling victim this year alone.

To disable SMS as a second factor on your Cloud MFA rules, please follow these steps:

  1. Log in to your Cloud USS dashboard
  2. Navigate to Security Modules -> MFA -> Rules and edit any rules that reference MFA authentication. Bypass rules will not need to be amended, for example:

  1. Double click the "MFA" rule(s) one at a time to open the editor. It is recommended to move the SMS/Email tile to the end of the Selected Conditions column using the up and down arrows, so that SMS is used as a last resort
  2. Click the Save button
  3. Once you have confirmed that users are no longer receiving SMS messages and that they are authenticating with other methods, such as the Authenticator App, you can safely delete it from your rule.


How did we do?